Earlier quoted context omitted.
And of course client side certificates. It's a pity they are rarely available as an option on public websites.
The UX for client certificates is horrific , especially if you choose the more secure approach of storing them on a smart card.
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
351–360 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#352Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#353Earlier quoted context omitted.
I've always thought the Post Office should offer something like Option #1.
That way you end up with the same issues as we have now with SIM swapping: Post Office employees are not more reliable and not necessarily more careful with their credentials than people who can give you a new SIM card.
I would bet that the post office employees are a bit less susceptible to the “hurry up and hit your metrics” pressure than someone at the Verizon call center.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#354Earlier quoted context omitted.
WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…
I can't make sense of your explanation. In 1) I don't think my YubiKey knows anything about the sites I use it for? It just creates keys, so a phishing site could presumably still steal the key created by YubiKey and pass it on to the real site. 2) My fingerprints definitely don't know anything about web sites. So WebAuthn being unphishable has nothing to do with fingerprints. It is only incidental that some devices…
The browser will only give access to the Yubikey token for a specific domain name - so if the attacker phishes for examle.org, rather then example.org, then there is just no tokens (signing keys) available the Yubikey could use and give to the browser.
In the early days WebUSB in Chrome had bugs that allowed to bypass that same origin check but that has been fixed 3 years ago.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#355Earlier quoted context omitted.
Short answer: they lose less money from people getting frustrated than the massive cost of real support
Maybe they would have more users with real support.
The Whatsapp purchase worked out to about $30/user, though proably factored in both further growth and the potential competitive risk.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#356Earlier quoted context omitted.
> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…
This depends on how it works. It is perfectly possible for games to be sold digitally online with no drm, such that you could easily (without requiring uncommon technical know-how) copy it to a flash drive and run it on a computer with no internet connection. Of course, games sold this way are extremely easy to pirate, because it is, essentially, pre-cracked. But one can distribute a product like this, and on occasio…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#357Earlier quoted context omitted.
Everyone already pays the same operational burden with their house keys, which are far more difficult to manage for the average person (as they leave the house constantly). It's worked fine for hundreds of years.
If you lose your house keys, you get a lock smith to break into your house for you - your house doesn't become unusable forever more. If you ever need to have this done, you'll realise how much house keys and door locks for many cases really only stop the opportunistic "pull the handle and see if it opens" attack. If your door has above average security they'll need to drill the lock, but the time I had to call one t…
Same with 2FA. Just like a Locksmith it's a "human in the loop" situation where you'll need to give identification etc.
The rest of your post isn't relevant it's just about picking door locks.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#358Earlier quoted context omitted.
Everyone already pays the same operational burden with their house keys, which are far more difficult to manage for the average person (as they leave the house constantly). It's worked fine for hundreds of years.
House keys don't just randomly break the way electronics sometimes do, though.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#359Earlier quoted context omitted.
"there's no second hand market for my game purchases" is an integral part of that reasoning. Why don't we just fix that too.
Even if there were a 2nd hand market, prices would likely be lower than the brand new price paid days after release. It's that brand new price Facebook would be refunding after a ban. So the same perverse incentive exists even with a 2nd hand market.